LoFP LoFP / administrative scripts that retrieve certain website contents

Techniques

Sample rules

Windows PowerShell User Agent

Description

Detects Windows PowerShell Web Access

Detection logic

condition: selection
selection:
  c-useragent|contains: ' WindowsPowerShell/'

Windows WebDAV User Agent

Description

Detects WebDav DownloadCradle

Detection logic

condition: selection
selection:
  c-useragent|startswith: Microsoft-WebDAV-MiniRedir/
  cs-method: GET